Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
9
Global rank
5 infographic chevron month
Month rank
13 infographic chevron week
Week rank
0
IOCs

Vidar is a dangerous malware that steals information and cryptocurrency from infected users. It derives its name from the ancient Scandinavian god of Vengeance. This stealer has been terrorizing the internet since 2018.

Trojan
Type
ex-USSR
Origin
1 December, 2018
First seen
30 August, 2026
Last seen

How to analyze Vidar with ANY.RUN

Type
ex-USSR
Origin
1 December, 2018
First seen
30 August, 2026
Last seen

IOCs

IP addresses
142.251.13.94
48.209.138.168
23.52.181.141
2.17.100.129
142.250.154.132
142.251.154.119
142.251.127.93
104.26.8.66
104.20.20.189
142.251.14.94
57.153.246.3
2.16.241.218
151.101.65.91
104.102.49.12
142.251.110.100
104.18.214.225
151.101.1.91
54.192.35.45
48.209.133.15
13.33.53.24
Hashes
81b2bd4ea98c8db66554fbc8d7637a1a69a130f331feb732b75caab4c4868fd5
5c3a5b578ab9fe853ead7040bc161929ea4f6902073ba2b8bb84487622b98923
1a0ec73a3ca7f354865d6b95401c50627fdf5a9b0da763a6f75fa818fd775b55
1fdd0b259b84f4ec7478d7fadabf0514dc8952ae2cf24dfa9520cd6475b91a7d
3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
226eec4486509917aa336afebd6ff65777b75b65f1fb06891d2a857a9421a974
32d83ff113fef532a9f97e0d2831f8656628ab1c99e9060f0332b1532839afd9
9b1fbf0c11c520ae714af8aa9af12cfd48503eedecd7398d8992ee94d1b4dc37
20de375707692099b3132084695377ce5fec0aec05813dedcce094b8eda44386
b4714676c161538a3b43173d17e0958a43f7ccabb65e6061a1a117ca7f54baab
c6fae744c9b3ea5dea4f219caa312df7e1f74f5d43d723c17ecc72089133dbe3
f9a75024e53f8a3e5ef92e12c87457fbfacc5508a5d7fbdde9126ee267e8b70b
d4d96f480e8246a7712c4bfa0eb8177f122f67c31f28f4ab133cbb1c2c05f747
c73b822c3598e2c68f2a09a42f85de10adececb9bcf838279fc93f1c37012b1f
08206401d5e061483e80d87b7973bb6ea9738e6d813d4726190520f9fba9aa0a
9c1dc36d319382e1501cdeaae36bad5b820ea84393ef6149e377d2fb2fc361a5
7bfbc8202b8cdbdcc597a0e789240f0dc0b0e94fa6597e576eaf436bc6223e18
f3bcc4a3ae6cd03e08ec48411b6927a0a163af6f92384279c1dd7afcb7f52293
07e8d69985547e670f5752809928fb887516ddd67e56d24c1323b4abc88723b3
2686ca32be23bf44a4a56a168ead9c6bba56f9468f7796e243042d8b6598265e
Domains
region1.analytics.google.com
e125010.dscb.akamaiedge.net
econventa.com
firefox-settings-attachments.cdn.mozilla.net
sites.google.com
googlehosted.l.googleusercontent.com
cdn-production-opera-website.operacdn.com
fonts.googleapis.com
eip-terr-eu.cdp1.digicert.com.akahost.net
translate.googleapis.com
g.ezoic.net
mozilla.map.fastly.net
edgedl.me.gvt1.com
cdn.econventa.com
www.youtube.com
lh3.googleusercontent.com
region1.google-analytics.com
www.mediafiredls.com
sb-ssl.google.com
go.microsoft.com
URLs
https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=url-parser-default-unknown-schemes-interventions&bucket=main&_expected=0
https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/url-parser-default-unknown-schemes-interventions/changeset?_expected=1743513175300&_since=%221726769128879%22
https://firefox.settings.services.mozilla.com/v1/
http://detectportal.firefox.com/canonical.html
http://detectportal.firefox.com/success.txt?ipv4
https://contile.services.mozilla.com/v1/tiles
https://spocs.getpocket.com/spocs
https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2026-03-08-09-54-23.chain
https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2026-09-24-19-49-17.chain
https://safebrowsing.googleapis.com/v4/threatlistupdates:fetch?$ct=application/x-protobuf&key=aizasyc7jsptds3am4tpx4r3nxis7imjbc5dovo&$httpmethod=post&$req=chuke25hdmnsawvudc1hdxrvlwzmb3gajwgfeaeagwoncauqbhgbigmwmdewardtgx4aahgjalrcyciciaioaroncaeqarobcg0iaraggaeiazawmtabel2qexocgandi_-vigigaigbgiciaxabghskdqgdeayyasidmdaxmaeq4qitggiycubgbd4iaiackaeajwgheaeagwoncacqbhgbigmwmdewarceshmaahgj9tw0wsiciaioarolcakqarozcg0icraggaeiazawmtabecqaahgjrotu3yiciaioaq==
https://sites.google.com/view/anvilsetup/anvil-setup
https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/ms-language-packs/records/cfr-v1-en-us
https://push.services.mozilla.com/
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://ocsp.digicert.com/
http://ocsp.r2m04.amazontrust.com/
https://fonts.googleapis.com/css?family=playfair%20display%3a400%2c700%2c900%7copen%20sans%3a400%2c400italic%2c600%2c600italic%2c700%2c700italic&display=swap
https://fonts.googleapis.com/css?family=staatliches%3ai%2cbi%2c700%2c400&display=swap
https://fonts.googleapis.com/css?family=google+sans:400,500|roboto:300,400,500,700|source+code+pro:400,700&display=swap
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4136
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 10033
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 12522
comments 0

What is Vidar malware?

Vidar is an information stealer trojan that was first identified in December 2018. It is either a fork of Arkei or the result of its evolution. Named after the god of vengeance from Scandinavian mythology, Vidar is used to steal information from infected systems, take screenshots, steal cryptocurrency, and more.

General description of Vidar malware

Vidar is presumed to have originated in a Russian-speaking country since the malware is configured to stop execution if it detects that it is being run on a machine that is located in one of the ex-USSR nations or on one that has a Russian keyboard layout.

Being another cyber threat that is available for purchase based on the MaaS (Malware-as-a-Service) business model, Vidar can be purchased on its “official” website for a hefty price tag of $700, at least for the PRO version. Though, a stripped-down version of the malware can be obtained for just $250.

According to the Vidar trojan analysis, malware is written in the C++ programming language. Purchasing account grants the attacker access to a control panel where the cybercriminal can set up the infostealer malware to target particular information on the victims’ PC. Like Arkei, cybercriminals need to take precautions to secure the main payload themselves, using crypto or a packer. The control panel displays the current builder version, user settings, malware status, and logs. It should be noted that Vidar data stealer uses domain names to search for C&C servers, where stolen data is being dropped, changing every four days. Though they are steadily changing, a constant response is required.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Vidar is capable of stealing text files in multiple formats, browser cookies and history, browser records, including data from TOR, as well as autofill value information, including banking and credit card details. Based on the Vidar analysis, the stealer malware can search for cryptocurrency wallet information, take screenshots and act as a message stealer, recording private messages from various software.

What’s more, Vidar is also known to be able to steal digital coins from offline wallets. In fact, holders of Litecoin, Bitcoin, Ethereum, Zcash, and DashCore are in potential danger, as these are the cryptocurrencies currently supported by this infostealer malware.

After collecting all targeted information, this stealer malware archives it and sends the stolen data to a control server, after which Vidar removes traces of its work and deletes itself from the system.

Vidar analysis

An analysis recorded in ANY.RUN malware hunting service allows us to take a closer look at the lifecycle of Vidar and perform Vidar analysis.

arkei execution process tree

Figure 1: A visual process graph generated by ANY.RUN

text report of the arkei malware analysis

Figure 2: The customizable text report provided by ANY.RUN is a perfect tool to share the results of an analysis

Vidar execution process

According to the Vidar analysis, after the user downloads and runs a malicious file, it spawns a child process and collects information from the infected system. Often, after the information was collected, the malware kills and deletes itself from the system through a command-line command.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

How to avoid infection by Vidar malware?

When spread via spam email campaigns like NanoCore or Agent Tesla, the Vidar stealer requires the user to download and run a malicious file to enter an active state and begin execution. Therefore, following some basic cybersecurity rules can ensure that users will stay safe from Vidar malware and the incident response team will work effectively.

As such, users should be careful when downloading attachments in emails from unknown senders. The best practice is to avoid downloading such files altogether, therefore not putting oneself in danger at all.

In addition, downloading only licensed software from trustworthy sources and avoiding gaming hacking clients greatly reduced the risk of being infected with malware such as Vidar trojan, which uses these attack vectors to infect victims.

The distribution process of Vidar

According to the Vidar trojan analysis, Vidar is distributed through spam email campaigns as a malicious attachment, like other malware. In addition, cases of Vidar being distributed using shady software and gaming hack clients have also been recorded. Vidar infostealer targets users all over the world, except some ex-USSR countries, including Russia.

How to detect Vidar using ANY.RUN?

Some malware creates files in which it named itself. You can find such info about Vidar trojan using ANY.RUN's Static Discovering during your Vidar analysis. Open either the "Files" tab in the lower part of the task's window or click on the process and then on the "More Info" button in the appeared window. After that, all you need to do is click on the file.

arkei vidar log file Figure 3: Vidar's log file

Conclusion

Vidar is a hazardous information stealer trojan, distributed as malware as a service. Thanks to its extensive stealer feature set, Vidar trojan can be used to retrieve a wide variety of information, including stealing select cryptocurrency coins from the users. Additionally, Vidar is capable of stealing data from TOR.

Thankfully, malware hunting services like ANY.RUN allows researchers to conduct extensive studies of malware samples in a secure environment, allowing them to spread information about the danger and develop effective countermeasures and incident response.

Create your free ANY.RUN account to analyze malware and phishing without limits!

HAVE A LOOK AT

BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
Sneaky 2FA screenshot
Sneaky 2FA
sneaky2fa
Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations.
Read More
HijackLoader screenshot
HijackLoader
hijackloader
HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
Salvador Stealer screenshot
Salvador Stealer
salvador
Salvador Stealer is a powerful, information-stealing Android malware designed to silently infiltrate systems, extract sensitive data, and exfiltrate it to cybercriminals. Often sold on underground forums, it is part of the growing ecosystem of “stealers-as-a-service” (SaaS) tools that target individuals and organizations alike.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More